PRIVACY POLICY
In Your Hand, Inc. (GDPR-, CCPA-, and International Compliance-Aligned)
This page explains how we handle personal data on the In Your Hand platform.
1. Introduction
LinkThis Privacy Policy explains how In Your Hand, Inc. (“In Your Hand,” “we,” “our,” or “us”) collects, uses, stores, discloses, and protects personal information when Users:
- Create an account
- Donate
- Open or operate a project
- Upload media or documents
- Use any feature of the platform
- Interact with communications or reporting tools
By using the platform, you agree to this Privacy Policy.
2. Legal Framework & Compliance Standards
LinkIn Your Hand processes data in compliance with:
- GDPR (EU General Data Protection Regulation)
- CCPA/CPRA (California Consumer Privacy Act / Privacy Rights Act)
- Children’s privacy laws (COPPA)
- NY State Privacy & Cybersecurity rules
- U.S. nonprofit data handling regulations
- AML/CFT & KYC/KYB obligations under U.S. federal law
- International data transfer standards
If any local laws provide stronger rights, In Your Hand will honor them.
3. Categories of Personal Data We Collect
LinkWe collect different levels of data depending on the user category.
3.1 General Users
- Name
- Email address
- Password (encrypted)
- Device and browser information
- IP address and geolocation
- Usage statistics
- Communication preferences
3.2 Donors
Additionally:
- Donation amounts and history
- Payment method (tokenized by payment processor)
- Billing region
- Gift Aid / tax receipt data
- Anonymity preferences
3.3 Individual Project Owners
Additional required data:
- Full legal name
- Date of birth
- Government-issued ID
- Biometric verification (if requested)
- Address and proof of address
- Phone number
- Bank account or payout information
- Uploaded documents, invoices, receipts
- Photos, videos, field reports
3.4 Institutional Partners
We collect:
- Organization registration documents
- Tax ID or equivalent
- Board resolution
- Authorized signatory information
- Incorporation certificate
- Bank verification documents
- Sanctions screening data
3.5 Beneficiaries (Indirect Data Collection)
We may receive:
- Age group
- Region or location
- Needs assessment data
- Non-identifying demographic data
We do not request or store:
- Government IDs of beneficiaries
- Sensitive personal data unless legally required
4. Sensitive Data Processing (AML / KYC / KYB)
LinkTo comply with U.S. law, In Your Hand must process:
- Identity documents
- Sanctions screening results
- Watchlist data (OFAC, UN, EU, UK)
- Risk scoring
- Fraud detection signals
- Criminal history indicators (where legally permissible)
5. How We Use Personal Data
LinkWe process personal data to:
- Provide platform services
- Verify identity & prevent fraud
- Conduct AML/CFT & sanctions screening
- Process donations and issue receipts
- Manage fundraising projects
- Communicate with users
- Ensure transparency and donor protection
- Improve the platform experience
- Conduct audits and legal compliance reviews
We will not use your data for:
- Selling to third parties
- Behavioral advertising
- Profiling unrelated to safety or fraud prevention
6. Legal Basis for Processing (GDPR)
LinkWe rely on these lawful bases:
6.1 Legal Obligation
AML, KYC, sanctions screening, financial recordkeeping.
6.2 Contractual Necessity
User accounts, project operations, donor receipts.
6.3 Legitimate Interests
Fraud prevention, safety monitoring, platform security.
6.4 Consent
Email marketing, optional media uploads, cookies. You may withdraw consent at any time.
7. Data Sharing and Third-Party Disclosures
LinkWe share data only when necessary and only with:
7.1 Payment Processors
- Stripe
- PayPal
- Banking partners
Data shared:
- Donation amount
- Donor region
- Payment token (never full card numbers)
7.2 Identity & Verification Providers
For KYC/KYB:
- Onfido, Veriff, Jumio, Stripe Identity
We share:
- Photos
- ID documents
- Compliance metadata
7.3 Sanctions & AML Screening Providers
- LexisNexis
- World-Check
- Government watchlists
7.4 Cloud Hosting & Security Services
- Encrypted data storage
- Logging and monitoring systems
7.5 Legal Obligations & Regulatory Authorities
In Your Hand may disclose information to government or regulatory bodies when required by:
- U.S. federal law (IRS, FinCEN, OFAC)
- Foreign financial regulations
- Court orders or subpoenas
- Law enforcement investigations
- AML/CFT reporting requirements
- Sanctions compliance
- Mandatory Expenditure Responsibility reports
7.6 Fraud Prevention & Security Providers
We may share data with cyber-security partners to:
- Prevent fraud
- Identify malicious activity
- Protect donor payments
- Secure platform systems
This includes IP monitoring, bot detection, behavioral anomaly scanning, and device fingerprinting.
7.7 No Sale of Personal Data
Under CCPA and GDPR, In Your Hand:
- Does NOT sell personal data
- Does NOT rent or trade personal information
- Does NOT use donor data for third-party marketing
We only share data necessary for security, identity verification, donation processing, and compliance obligations.
8. International Data Transfers
LinkAs a global nonprofit platform, In Your Hand may process and store data:
- In the United States
- In the European Union
- In other jurisdictions where our secure cloud hosts operate
We ensure compliance through:
- Standard Contractual Clauses (SCCs)
- GDPR Article 46 appropriate safeguards
- Data minimization
- Encryption at transit and rest
Users in the EU acknowledge that their data may be transferred to the United States under these legal safeguards.
9. Data Retention Periods
LinkIn Your Hand retains personal data based on legal, regulatory, and operational requirements.
9.1 Standard User Data
Retained as long as the account is active, plus 3 years.
9.2 Donor Records
Financial records must be retained for 7 years (IRS compliance).
9.3 KYC / KYB, AML, Sanctions Screening Data
Stored for 7–10 years, as required by U.S. federal law and international AML standards.
9.4 Project Documentation
Receipts, invoices, media, and reports retained for minimum 7 years.
9.5 Request for Deletion
Users may request deletion, except where data is required for:
- Legal compliance
- Fraud prevention
- Ongoing investigations
- Mandatory financial documentation
- Historical donor tax records
10. Your Data Protection Rights
LinkDepending on your jurisdiction, you may have some or all of the following rights:
10.1 Right to Access
You may request a copy of personal data we hold about you.
10.2 Right to Rectification
You may correct inaccurate or incomplete data.
10.3 Right to Deletion (“Right to Be Forgotten”)
You may request deletion unless retention is required by:
- AML regulations
- IRS rules
- Donor tax records
- Fraud investigations
- Expenditure Responsibility requirements
10.4 Right to Restrict Processing
You may limit the processing of your personal data.
10.5 Right to Data Portability
You may request a structured, machine-readable export of your information.
10.6 Right to Object (GDPR)
You may object to:
- Marketing communications
- Profiling not related to fraud prevention
10.7 Right to Withdraw Consent
If processing is based on consent, you may withdraw consent anytime.
10.8 California Rights (CCPA/CPRA)
California residents may request:
- Categories of personal data collected
- Categories of sources
- Purposes of collection
- Categories of third parties receiving data
- Access, correction, deletion
- Opt-out of sale (not applicable to our operations)
12. Children’s Privacy (COPPA Compliance)
LinkThe platform is not intended for users under 18. We do not knowingly collect data from minors.
Project Owners must obtain documented parental or guardian consent for:
- Any media involving children
- Stories or updates referencing identifiable minors
Violations result in:
- Immediate removal of content
- Potential account termination
- Safeguarding investigation
13. Security Measures
LinkIn Your Hand protects data through:
- End-to-end encryption
- SSL/TLS for all connections
- Encrypted storage (AES-256)
- Role-based access control
- Two-factor authentication (for internal systems)
- Intrusion detection and prevention systems
- Regular penetration testing
- Routine security audits
Despite strong protections, no system is 100% secure. Users are responsible for safeguarding their passwords and devices.
14. Data Breach Policy
LinkIf a breach affects personal data:
- Incident will be investigated immediately.
- Affected users will be notified within the legally required period (GDPR: 72 hours).
- Authorities will be notified when required.
- Mitigation measures and corrective actions will be implemented.
15. How We Use Automated Decision-Making
LinkWe may use algorithmic tools for:
- Fraud detection
- Sanctions monitoring
- Identity authentication
- High-risk activity alerts
We do not use algorithms to make:
- donation decisions
- beneficiary decisions
- eligibility judgments without human oversight
16. Third-Party Links
LinkThe platform may link to external websites. In Your Hand is not responsible for those sites’ privacy practices.
17. Changes to This Privacy Policy
LinkIn Your Hand may update this policy as needed.
Changes are effective upon posting. Continued use of the platform constitutes acceptance of updated terms.
18. Contact Information
LinkFor privacy-related questions, data access requests, or deletion requests:
Users in the EU may also file a complaint with their local Data Protection Authority.
If any part of this Privacy Policy is found unenforceable, the remaining provisions will remain in effect.
